AI Act Enforcement 2026: Why the CFO Signs Off on "High-Risk AI System" Definitions
The 2026 AI Act checkpoint still lands on CFO-owned disclosure language, but the high-risk calendar changed. Article 50 transparency and GPAI enforcement remain live issues; high-risk obligations need 2027/2028 Omnibus caveats.
In brief: On 2 August 2026, Article 50 transparency obligations and Commission enforcement powers over GPAI model providers remain key checkpoints. Under the 7 May 2026 AI Omnibus political agreement, stand-alone high-risk rules move to 2 December 2027 and product-embedded high-risk rules to 2 August 2028, pending final Official Journal text. Article 99 fines still make terminology discipline a CFO disclosure issue.
The disclosure-risk problem
Article 3 defines 68 terms. Six determine whether your company faces the high-risk compliance stack: AI system, high-risk AI system, substantial modification, deployer, provider, GPAI model. A seventh, systemic risk, determines whether a GPAI model triggers Article 55 enhanced obligations that have applied since 2 August 2025 and that the Commission can enforce from 2 August 2026.
The AI Act Service Desk timeline identifies 2 August 2026 as the date when Commission enforcement powers for GPAI model providers enter into application. From that date, how your filings described your AI systems may become relevant evidence in any AI disclosure, regulator-information, or investor-disclosure review.
For SEC registrants, the principal financial officer signs Form 10-K and certifies annual and quarterly reports; investor materials should be controlled through the disclosure process when they discuss material AI claims. If risk privately classifies a production model as high-risk while MD&A calls it "automated decision support", filing and internal assessment disagree. In April 2025, the SEC and DOJ charged Albert Saniger, former CEO of Nate, Inc., over alleged false AI automation claims; the SEC alleged Nate relied substantially on contract employees to manually input orders.
The stakes
Article 99 establishes three fine tiers. Higher of a euro cap or percentage of worldwide turnover applies to undertakings. For SMEs, the lower of the two applies.
| # | Tier | Trigger | Cap (euro) | Cap (% worldwide turnover) |
|---|---|---|---|---|
| 1 | Tier 1 | Prohibited AI practices (Article 5) | EUR 35,000,000 | 7% |
| 2 | Tier 2 | Provider, authorized rep, importer, distributor, deployer, notified body, transparency obligations (Art. 16, 22, 23, 24, 26, 31, 33, 34, 50) | EUR 15,000,000 | 3% |
| 3 | Tier 3 | Incorrect or misleading information to authorities | EUR 7,500,000 | 1% |
Tier 2 attaches to the operator and transparency obligations that attach once an AI system is in scope as high-risk or subject to Art. 50 transparency rules. If production docs call a system a "model" while the risk register calls it a "high-risk AI system" and the 10-K calls it "AI-powered automation", the definitional drift is an evidentiary problem. Tier 3 attaches separately: if the regulator asks for your classification rationale and receives inconsistent documents, the "incorrect or misleading information" tier may apply.
The practical CFO question is what evidence exists that AI claims were reviewed before they reached investor-facing or regulator-facing materials. A glossary is not a formal legal defense; it is one process artifact showing who approved which term, when, and against which regulatory definition.
The 2026 checkpoint and EU market scope
The AI Act applies in phases:
- 2 February 2025 — prohibitions and AI literacy obligations applied
- 2 August 2025 — GPAI governance rules applied
- 2 August 2026 — Article 50 transparency obligations and Commission enforcement powers against GPAI model providers remain key 2026 checkpoints
- 2 December 2027 — planning date for stand-alone high-risk AI systems under the 7 May 2026 AI Omnibus political agreement, pending final legal text
- 2 August 2028 — planning date for high-risk AI systems embedded in regulated products under the same political agreement, pending final legal text
How terminology governance addresses this
Compliance Glossary is not a GRC platform and does not replace risk management or conformity assessment. It provides one artifact: a governed, four-eyes-approved, audit-trailed glossary of the terms that appear in every AI Act deliverable and external disclosure. The 68 Article 3 definitions are available through the AI Act glossary packet.
- Four-eyes approval. The person who drafts "high-risk AI system" cannot approve it. A second authorized reviewer must verify the wording against Article 3 before it becomes canonical.
- Version history. Every edit is recorded with author, timestamp, prior wording, approver, and rationale. When a regulator asks when you classified a system as GPAI with systemic risk, the answer is a timestamped record.
- Audit trail with timestamps. A timestamped audit trail is concrete "what actions did you take" evidence.
- Compliance scanner. Deterministic pattern matching flags pages using "algorithm" or "tool" when the governed term is "high-risk AI system", or "user" where it should be "deployer".
- CSV export with full version history (PDF audit-package export on the 2026 roadmap). One export produces the regulator-facing artifact: every approved term, approver, version, and date. Disclosure counsel, D&O underwriters, and EU conformity-assessment bodies all ask for this.
Compliance Glossary is not a substitute for SOX disclosure controls, ICFR, or a GRC platform.
For current pricing, see the Atlassian Marketplace.
Frequently asked questions
Why does the CFO personally sign off on AI Act terminology?
For SEC registrants, the principal financial officer signs Form 10-K and certifies annual and quarterly reports. Investor materials should be controlled through the disclosure process when they discuss material AI claims. If filings describe a system as ordinary software while internal materials classify it differently, the inconsistency is a disclosure-control issue.
What are the AI Act fine tiers?
Article 99 sets three tiers (higher of cap or turnover percentage). Tier 1 prohibited practices: EUR 35 million or 7% of global turnover. Tier 2 covers provider, authorized rep, importer, distributor, deployer, notified body, and transparency obligations (Art. 16, 22, 23, 24, 26, 31, 33, 34, 50) at EUR 15 million or 3%. Tier 3 for incorrect or misleading information to authorities: EUR 7.5 million or 1%. SMEs pay the lower of the two.
What changes on 2 August 2026?
After the AI Omnibus political agreement, 2 August 2026 is best treated as a narrower checkpoint: Article 50 transparency obligations and Commission enforcement powers for GPAI model providers. Stand-alone high-risk AI rules move to 2 December 2027 and product-embedded high-risk rules to 2 August 2028 as planning dates pending final legal text. Prohibitions applied from 2 February 2025; GPAI obligations applied from 2 August 2025.
How does a terminology glossary reduce AI disclosure risk?
High-risk AI system, substantial modification, deployer, provider, GPAI model, and systemic risk each have Article 3 definitions that determine which obligations apply. A shared, approved, audit-trailed glossary records who approved which wording, when, and against which regulatory text — reasonable-care evidence at the individual-liability level the SEC has flagged.
This article is informational and is not legal advice. Consult qualified counsel for AI Act compliance decisions specific to your facts.
Sources checked
- Regulation (EU) 2024/1689 — AI Act legal text, Articles 3, 50, 55, 99, and 113.
- European Commission AI Act page — implementation timeline and AI Omnibus status.
- Council AI Omnibus political agreement — 2 December 2027 and 2 August 2028 high-risk planning dates.
- AI Act Service Desk Article 50 — transparency obligations.
Get the 68 Article 3 definitions into governance before the next AI Act checkpoint
For current pricing, see the Atlassian Marketplace.
Evaluate in Confluence Read the Security Whitepaper